Trust Center

Everything a security review would ask us — published.

Sub-processors, data residency, encryption posture, incident response, responsible disclosure and audit reports. If your review needs a document, request it from security@binaryaiq.com.

At a glance

The facts most review packs open with.

Programme alignment
DPDP Act 2023 · ISO 27001 (controls mapped) · ISO 27701 (privacy management) · SOC 2 Type II in progress
Primary data residency
ap-south-1 (Mumbai). Optional EU (Frankfurt) or US (N. Virginia) on request.
Encryption at rest
AES-256, per-tenant key scoping, KMS-managed
Encryption in transit
TLS 1.3 with strong cipher preference; HSTS enforced
Authentication
Email/password with MFA, SSO via SAML 2.0 or OIDC, SCIM provisioning
Access control
Role-based, scope-limited to organisation, legal entity, business unit or department
Audit trail
Append-only per entity; actor, IP, session and impersonation context recorded on every write
Backups
Point-in-time recovery for 30 days; encrypted backups replicated across zones
Independent testing
Annual black-box penetration test by an accredited third party; results shared under NDA
Sub-processors

Every third party that touches customer data — enumerated.

The current register is published below. Customers are notified before a new sub-processor is added. The full addendum, with contractual controls, is available in the DPA on request.

Cloud infrastructure
Amazon Web Services (ap-south-1, Mumbai). Compute, storage, KMS.
Transactional email
Resend Inc. Address of record and delivery telemetry only; no message body retention beyond delivery.
Product analytics
First-party analytics on Binary infrastructure. No third-party tracking scripts in the customer application.
Error monitoring
First-party error capture on Binary infrastructure. Stack traces and request context only; no request bodies.
Support tooling
Enumerated per contract; access requires a support case and audited approval.
Incident response

What happens if something goes wrong.

Detect

Continuous monitoring across authentication, data plane and infrastructure. Anomalies raise a security incident record within minutes.

Contain and assess

Named incident commander, tenant impact assessment, forensic log capture. Scope is established before any external communication.

Notify

Affected customers receive a factual notification with scope, timeline and mitigation. For DPDP Section 8(6) events, we support the customer's notification to the Board and data principals inside the statutory window.

Responsible disclosure

Reporting a vulnerability.

Send vulnerability reports to security@binaryaiq.com. Include a description, reproduction steps and impact. Encrypted mail is welcomed — request our public key in first contact.

We acknowledge within 2 business days, triage within 5 business days and remediate on a severity-based timeline. Coordinated disclosure is expected; researchers acting in good faith are not pursued.

Testing must not access other customers' data, disrupt service or use social engineering against staff. Automated scanners against production are not permitted.

Requesting documents

What we share, and how.

Data Processing Addendum
Available on request. Pre-signed template covers DPDP, GDPR and standard controller-processor terms.
Sub-processor register
Published above. Customers are notified before a new sub-processor is added.
Security whitepaper
Control-by-control walkthrough. Shared under NDA to prospective customers.
Penetration test summary
Executive summary shared under NDA. Full report available to enterprise customers with an active MSA.
SOC 2 / ISO reports
Shared under NDA when available. SOC 2 Type II is in progress; ISO 27001 controls are mapped.
Standard security questionnaire
We complete SIG Lite, CAIQ and custom questionnaires within 5 business days of receipt.